PT-2025-29861 · Wegia · Wegia

Elisangelasilvademendonca

·

Published

2025-07-11

·

Updated

2025-07-25

·

CVE-2025-53932

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.5
Description WeGIA is an open-source web manager designed for Portuguese-speaking users and charitable organizations. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the cadastro adotante.php endpoint. Attackers can inject malicious scripts through the cpf parameter.
Recommendations Update to version 3.4.5 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-09267
CVE-2025-53932
GHSA-3VFW-749Q-QP6R

Affected Products

Wegia